Last updated August 5, 2026
lockdin exists to turn your professional background into tailored résumés, so the data you give it is inherently personal: your name and contact details, résumé files you upload, LinkedIn data-export archives, public GitHub profile and repository metadata you ask us to fetch, target-role preferences (titles, locations, compensation), the résumés we generate for you, and the application history you track. We also store your email address and authentication credentials (or your Google account identifier if you sign in with Google), and standard technical logs.
Your data is used for exactly one product: building your profile, matching job listings against it, and generating and revising tailored résumés you asked for. Résumé and profile text is sent to Anthropic's Claude API for parsing, enrichment suggestions, match scoring, and résumé generation. Anthropic processes it as a service provider and does not train models on this API data. Job listings come from public and licensed sources (ATS feeds, job-board APIs); your profile is scored against them on our side.
We never sell your data, never share your résumé or profile with employers or anyone else, and never auto-apply anywhere on your behalf. You always click send.
Five companies process data on our behalf, and this is the complete list. Supabase stores everything (Postgres, encrypted at rest, hosted in the US) with row-level security so only your authenticated account can read your rows. Anthropic receives résumé and profile text to do the parsing, matching and generation described above. Stripe handles payments — card numbers never touch our servers. Vercel hosts the site, so it processes the request data any web host sees, and also provides the traffic and performance measurement described in the next section. Sentry receives error reports when something breaks — what failed and where, not what you wrote. We do not put résumé text, profile content or the text of feedback you send into those reports, we strip the query string off any URL they mention, and we leave off the option that would attach your request headers, cookies or IP address.
The optional browser extension keeps your signed-in session in the browser's own extension storage — the whole session, including the token that refreshes it, which is what lets it stay signed in — and caches the match scores and in-progress tailoring for tabs you are working in. It reads a page only when you ask it to, on the tab you are looking at; it holds no permission to read sites in the background. Captured postings go to your account and nowhere else. Signing out of the extension clears all of it.
We set no advertising or cross-site tracking cookies, and there is no ad network, data broker or third-party marketing tag anywhere on the site.
What we do set: the cookies Supabase needs to keep you signed in, and — only if you arrive through someone's invite link — a lockdin_ref cookie that remembers who invited you so they get credited when you sign up. It lasts 30 days, is readable only by our server, and is deleted the moment your account is created. Vercel Analytics and Speed Insights measure page views and load times without cookies and without building a profile of you across other sites.
Your data is kept while your account is active. Delete your account (or email us) and your profile, sources, résumés, and application history are deleted; billing records required by tax law are retained by Stripe. You can export your profile and résumés at any time — the PDFs are yours.
Access, correction, export, and deletion are available in-app or by email, wherever you are. If you're in the EU/UK, these map to your GDPR rights and our lawful basis is the contract we have with you (plus legitimate interest for security logging). We don't use your data for advertising and we don't track you across other sites.
The data controller is Elvin Topalov, trading as lockdin, reachable at the email in section 08. Our processors are in the United States, so using lockdin from the EU or UK means your data is transferred there; those transfers rely on the Standard Contractual Clauses in our agreements with the processors named in section 03. If you are unhappy with how we have handled your data you can complain to your national data-protection authority.
If this policy changes materially, we'll note it here and flag it in-app before it takes effect.
Privacy questions, data requests, and deletions: privacy@joinlockdin.com.